Description
Free models fail when shell or read permissions are denied
Description
Using OpenCode v2.0.16 with OpenCode free models such as opencode/big-pickle.
If either the shell or read permission is set to deny, requests to free models fail with:
Error: OpenCode's free tier can only be used from within OpenCode
For example:
{
"action": "shell",
"resource": "*",
"effect": "deny"
},
{
"action": "read",
"resource": "*",
"effect": "deny"
}
Changing both permissions to allow immediately makes the error disappear:
{
"action": "shell",
"resource": "*",
"effect": "allow"
},
{
"action": "read",
"resource": "*",
"effect": "allow"
}
The behavior can be reproduced without restarting OpenCode: changing these permissions while OpenCode is running changes whether the next request succeeds or fails.
Expected behavior
Tool permissions should control whether the model can use those tools.
Denying shell or read should not cause a request made from the official OpenCode CLI to be identified as coming from outside OpenCode.
Actual behavior
Disabling these tools causes OpenCode free-tier requests to be rejected as if the request were not originating from OpenCode.
Environment
Plugins
Reproduced with the official CLI. The behavior is permission-dependent.
OpenCode version
2.0.16
Steps to reproduce
- Run OpenCode v2.0.16.
- Select a free OpenCode model, for example
opencode/big-pickle.
- Set
shell or read to deny.
- Start a new session or send a simple prompt such as
Hello.
- The request fails with:
Error: OpenCode's free tier can only be used from within OpenCode
- Change both
shell and read to allow.
- Send the same prompt again.
- The request succeeds.
Screenshot and/or share link
No response
Operating System
Windows 11 25H2 26200.9457
Terminal
PowerShell 7.6.6.0-x64
Description
Free models fail when
shellorreadpermissions are deniedDescription
Using OpenCode v2.0.16 with OpenCode free models such as
opencode/big-pickle.If either the
shellorreadpermission is set todeny, requests to free models fail with:For example:
{ "action": "shell", "resource": "*", "effect": "deny" }, { "action": "read", "resource": "*", "effect": "deny" }Changing both permissions to
allowimmediately makes the error disappear:{ "action": "shell", "resource": "*", "effect": "allow" }, { "action": "read", "resource": "*", "effect": "allow" }The behavior can be reproduced without restarting OpenCode: changing these permissions while OpenCode is running changes whether the next request succeeds or fails.
Expected behavior
Tool permissions should control whether the model can use those tools.
Denying
shellorreadshould not cause a request made from the official OpenCode CLI to be identified as coming from outside OpenCode.Actual behavior
Disabling these tools causes OpenCode free-tier requests to be rejected as if the request were not originating from OpenCode.
Environment
v2.0.16Plugins
Reproduced with the official CLI. The behavior is permission-dependent.
OpenCode version
2.0.16
Steps to reproduce
opencode/big-pickle.shellorreadtodeny.Hello.shellandreadtoallow.Screenshot and/or share link
No response
Operating System
Windows 11 25H2 26200.9457
Terminal
PowerShell 7.6.6.0-x64